
A concise, fact-based update for security and risk professionals. Core technical stories first, followed by broader risk & governance context.
🔐 Core Security Intelligence
1) “RMPocalypse” breaks AMD confidential computing guarantees (CVE-2025-0033)
What’s new:
ETH Zurich researchers disclosed a flaw in AMD SEV-SNP’s Reverse Map Table (RMP) initialization that lets a malicious hypervisor corrupt RMP entries and undermine integrity for confidential VMs. AMD says EPYC and EPYC Embedded parts are affected; OEM BIOS updates are being prepared. Microsoft noted Azure Confidential Computing clusters will be updated and may require reboots.
Source: SecurityWeek.
Why it matters:
SEV-SNP is used to protect cloud workloads from a compromised host. A weakness in the RMP setup erodes that trust boundary, enabling attacks like fake attestation or code injection against otherwise “shielded” guests.
Defenses:
- Coordinate with your cloud and OEM for firmware rollout. Track BIOS/firmware advisories for EPYC platforms and plan maintenance windows for required host reboots; verify post-patch attestation baselines before restoring high-sensitivity workloads.
- Constrain blast radius for confidential VMs. Treat CVMs like high-value assets even when “encrypted and attested”: minimize secrets in memory, require short-lived tokens, and restrict host-level tooling that could observe guest behavior.
- Harden the hypervisor and supply chain. Enforce least-privilege on host management paths, rotate host credentials and KMS policies, and continuously validate attestation results to catch downgrade or replay attempts.
Expert Insight:
Confidential computing raises the floor, not the ceiling. Trust still hinges on tiny implementation details like RMP initialization. Security teams should treat attestation as a signal to be verified (and monitored) rather than a permanent guarantee, and keep rollback/evacuation runbooks handy for fleet-wide firmware events.
2) Windows 10 reaches end-of-support while still on 40%+ of devices
What’s new:
Microsoft ended free security updates for Windows 10 today (Oct 14, 2025). Extended Security Updates (ESU) are available through Oct 13, 2026 for a fee ($61 per commercial device in year one, doubling annually), with separate consumer options and some regional exceptions. Third-party telemetry suggests hundreds of millions of endpoints still run Windows 10.
Source: SecurityWeek.
Why it matters:
Unpatched Windows 10 estates will quickly accumulate critical exposure. Attackers reliably pivot to unsupported platforms with commodity exploits, and legacy business apps often slow migration—creating long tails of risk.
Defenses:
- Triage and segment stragglers. Inventory Windows 10 devices, isolate those handling sensitive data, and apply strict egress controls and application allow-listing until they are upgraded or decommissioned.
- Use ESU surgically. Enroll only systems that truly cannot migrate in time; pair ESU with aggressive patch SLAs, credential rotation, and attack surface reduction rules to contain residual risk.
- Harden identity and macros. Expect phishing and token theft to target lagging hosts—enforce phishing-resistant MFA, conditional access, and disable legacy protocols/macros that amplify post-exploit movement.
Expert Insight:
This is a board-level risk milestone. Treat today as a forcing function to clean up endpoint inventories, retire “unknown unknowns,” and align app owners behind a migration deadline. If a device is business-critical and cannot move, prove the compensating controls and put an expiry date on the exception.
3) Visa unveils “Trusted Agent Protocol” to separate shopper bots from agentic AI
What’s new:
Visa introduced a “Trusted Agent Protocol,” developed with Cloudflare and supported by partners like Microsoft, Shopify, and Adyen, to help merchants distinguish registered AI shopping agents from malicious automation during the holiday season. Visa says AI-driven shopping traffic is up 4,700% YoY; the protocol aims to standardize agent-merchant signaling without major checkout changes.
Source: Axios.
Why it matters:
Agentic commerce is arriving: autonomous assistants will browse, compare, and eventually buy. Without authentication and provenance, commerce flows are vulnerable to bot fraud, scraping, and basket abuse that look “AI-legit.”
Defenses:
- Adopt agent provenance signals early. If your platform supports it, pilot the protocol on high-risk SKUs and flash-sale flows; combine with bot management and WAF rules that down-rank unknown automations.
- Bind identity to payment and risk scoring. Correlate agent assertions with device fingerprints, issuer risk scores, and behavioral telemetry; challenge anything inconsistent before fulfillment.
- Monitor for protocol abuse. Assume attackers will spoof “trusted agent” headers—log and rate-limit by agent identity, rotate keys/registrations, and run canary offers to detect scraping masquerading as agents.
Expert Insight:
Commerce is about to inherit the bot problem from security at scale. A neutral, open signaling layer is a good start, but it only works if merchants and PSPs verify it with independent telemetry. Expect quick cat-and-mouse as fraud rings reverse-engineer agent claims.
🌐 Extended Reading / Broader AI Risk & Governance
UK warns: “highly significant” cyber incidents up 50% YoY
What’s new:
At the NCSC annual review, the UK reported a 50% year-over-year increase in “highly significant” incidents, with 204 attacks across the three most serious categories and 18 of national-scale impact. Ministers urged FTSE-350 boards to make cyber resilience a priority.
Source: Reuters.
Why it matters:
Even as AI defenses improve, operational exposure and supplier fragility are driving systemic risk. Leadership attention, incident rehearsals, and supplier continuity plans are now core governance duties—not optional hygiene.
⚠️ Updates / Follow-ups
No qualifying follow-ups in the past 24 hours.
(Reminder: we exclude previously covered stories unless there’s a material update.)
Summary Table
| Threat / Trend | Key Risk | Defense Highlights |
|---|---|---|
| AMD “RMPocalypse” (CVE-2025-0033) | Breaks SEV-SNP integrity via RMP init gap | Firmware rollouts; verify attestation; harden hypervisor. (SecurityWeek) |
| Windows 10 end-of-support (EOS) | Rapid growth of unpatched endpoint exposure | Segment stragglers; selective ESU; identity hardening. (SecurityWeek) |
| Trusted Agent Protocol for agentic commerce (Visa) | Bot spoofing and agent fraud at checkout | Adopt provenance signals; bind to risk scoring; detect spoofing. (Axios) |
| UK NCSC incident surge (governance context) | Board-level resilience and supplier fragility | Board oversight; scenario exercises; supplier continuity checks. (Reuters) |
Categories: Cybersecurity News
Leave a Reply